The UK’s banking watchdog, the Financial Conduct Authority, has rolled out a new framework for incident and third party reporting that places fresh demands on how financial institutions test, monitor and evidence digital resilience across their technology environments.
The rules are designed to standardise how firms identify, classify and report operational incidents, particularly those involving third party providers such as cloud platforms, data vendors and outsourced technology services. Regulators want earlier notification, clearer categorisation and more consistent follow up reporting as incidents evolve.
FCA director Mark Francis stressed that “digital resilience is being tested like never before, with firms facing growing online threats and increasing reliance on third parties to deliver the essential financial services consumers rely on.”

He pointed out that “these changes give firms clearer rules and practical guidance to better manage disruption, while supporting our ambition to be a smarter regulator, giving us better data to spot risks, share insights and strengthen sector wide resilience.”
Francis added that the regulator will increasingly use incident data to identify systemic weaknesses across the sector.
“Over time we will use this data to share insights and trends to help firms bolster their operational resilience and share relevant information with industry, where appropriate during widespread disruption, particularly in stressed market conditions,” he explained.
“And where disruption occurs at a third party, the data will help us see through firms’ supply chains to identify which services are the most exposed and help us identify potential critical third parties to the UK financial system,” Francis added.
No longer a compliance afterthought
For QA and software testing teams, this effectively turns incident reporting into a testable capability rather than a compliance afterthought.
Firms must demonstrate that detection systems, escalation workflows and reporting pipelines work reliably under real conditions, including disruptions originating outside their direct control.
That requirement is becoming more urgent as third party dependencies deepen across the sector. More than 40 percent of reported incidents in 2025 were linked to third party providers, highlighting how critical services, infrastructure and data increasingly sit beyond firm boundaries.
“Digital resilience is being tested like never before.”
– Mark Francis, FCA
Scrutining the new rules for QA Financial, London-based Michael Murphy, deputy CTO at Arqit, said the updated rules reflect a broader change in how operational risk must be managed.
“The FCA’s latest guidance reflects how operational risk is changing across the financial sector,” he said.
“As banks rely more heavily on third party providers, resilience is no longer just about protecting internal systems, it extends across a much wider and often more complex digital supply chain,” Murphy shared.

He believes that “clearer rules around incident and third party reporting are a positive step. They should help firms respond more quickly to disruption and give regulators better visibility into emerging risks.”
But, according to Murphy, they also highlight a deeper issue.
“If a growing share of incidents originate outside a firm’s direct control, then reporting alone can only go so far,” he explained. “The real challenge is maintaining control over critical data and services even when they sit on infrastructure or platforms operated by someone else.”
Murphy singles out one trend that is rapidly gaining momentum in the financial services space, and not just in the UK, not increase digital resilience and software safety controls.
“Encryption is playing a much bigger role than many organisations realise. If organsiations keep control of the keys and access policies protecting their data, they can operate on shared or third party infrastructure without giving up control,” he pointed out.
“That’s why approaches like confidential computing are gaining traction, because they allow sensitive workloads to remain protected even while they are being used.”
Testing incident reporting
For testing teams, the new regime introduces a need to validate not just systems, but the processes surrounding them.
Incident detection, classification and regulatory notification must be treated as integrated components of the technology stack, subject to continuous testing and verification.
That includes ensuring monitoring tools capture disruptions across third party environments, validating that alerts are triggered at the right thresholds and testing whether incident severity is assessed in line with regulatory expectations.
It also requires firms to prove that reporting timelines can be met under pressure, with accurate and complete information.
This focus on observable behaviour and evidence aligns closely with the FCA’s broader regulatory direction, particularly in artificial intelligence and model validation.
Through its AI Live Testing initiative, the regulator is pushing firms to move beyond static validation and test systems in real world conditions.

“We’re providing a structured but flexible space where firms can test AI driven services in real world conditions, all with our regulatory support and oversight and help from our technical partner, Advai,” said Ed Towers, head of department in the FCA’s advanced analytics and data science unit.
The programme is aimed at firms struggling to move AI systems from pilots into production, a challenge that mirrors wider issues in testing and assurance.
“Through live testing we want to help UK innovators move safely beyond ‘POC paralysis’, or what is often described as ‘perpetual pilots’,” Towers shared.
“We focus on both quantitative and qualitative factors to get a truly holistic understanding of the AI system.”
Importantly, the FCA defines AI as a full system rather than a standalone model, bringing governance, controls and human oversight into scope for testing.
“We broadly define the AI system as: the actual AI model, information on the deployment context and core risks … governance and human in the loop considerations, evaluation techniques as well as the input and output controls,” Towers explained.
“As banks rely more heavily on third party providers, resilience is no longer just about protecting internal systems.”
– Michael Murphy
Alongside live testing, the FCA is also setting expectations around how firms govern and validate the data underpinning their systems, particularly as synthetic data becomes more widely used in testing and model development.
Jessica Rusu, the FCA’s Chief Data, Information and Intelligence Officer, described synthetic data as a key enabler of innovation, while emphasising the need for strong controls.
“Synthetic data is one such technology,” she said recently, noting its potential to “unlock the value of data, enable experimentation, model development, and broader innovation across the financial system, all while maintaining strong privacy protections and public trust.”

She added that regulators want to encourage practical engagement while ensuring risks are addressed transparently.
“Open and practical conversations about how synthetic data is being used, where the challenges lie, and what’s needed to move forward responsibly,” Rusu remarked.
She was keen to stress that collaboration can help firms scale these approaches safely, noting that “we can lower the barriers to adoption, build confidence in new techniques, and build a more competitive, future ready financial system.”
For QA teams, this introduces new responsibilities around auditability, bias detection and performance validation. Synthetic data must be tested iteratively, benchmarked against real world performance and supported by clear documentation that regulators can interrogate.
Global shift towards testable resilience
The FCA’s reporting rules also sit within a wider push to align testing and resilience standards internationally, particularly as firms operate across jurisdictions and rely on shared technology infrastructure.
Through its partnership with the Monetary Authority of Singapore, the FCA is working to create shared environments where AI systems can be tested against real world data and regulatory expectations.

The regulator said the collaboration will support “safe and responsible AI innovation” while enabling firms to scale across markets with greater confidence in their testing and assurance processes.
Rusu said the initiative would see regulators “be championing safe and responsible AI innovation across UK and Singapore markets,” allowing firms to explore cross border opportunities and shape “the future of responsible AI innovation in finance.”
For QA and software testing teams, the direction is clear. Incident reporting, AI validation and third party oversight are converging into a single expectation.
Firms must be able to demonstrate, through continuous testing and measurable evidence, that their systems remain resilient, controlled and accountable.
In that environment, reporting an incident is no longer the end of the process. It is proof of whether the systems designed to detect, manage and communicate risk have actually been tested and are working as intended.
QA FINANCIAL EVENTS


Why not become a QA Financial subscriber?
It’s entirely FREE
* Receive our weekly newsletter every Wednesday * Get priority invitations to our Forum events *
REGULATION & COMPLIANCE
Looking for more news on regulations and compliance requirements driving developments in software quality engineering at financial firms? Visit our dedicated Regulation & Compliance page here.
READ MORE
- Banks confront rising agentic AI testing challenge
- Testing turns ‘reactive’ as documentation lags
- Inside UBS’s landmark testing challenge
- Bank of England raises the testing bar for frontier AI
- Tricentis, Tabnine and Snyk: the latest vendor and product news
WATCH NOW

QA FINANCIAL PODCASTS



